Privacy Policy

Effective September 27, 2026

This Privacy Policy explains what information lugnote.com ("LugNote", "we", "us") collects when you use the LugNote website and application (the "Service"), what we do with it, who we share it with and the choices you have.

The short version: we collect what is needed to run a vehicle record-keeping service, we do not sell it, we do not show ads, and we do not build advertising profiles.

1. Who this policy covers

This policy covers people who visit our website, hold a LugNote account, or are members of a household in LugNote. The Service is operated from, and hosted in, the United States, and is offered to people located in the United States. It is not offered to people in the European Economic Area, the United Kingdom or Switzerland.

The Service is not directed to children. You must be at least 16 to use it, and we do not knowingly collect information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.

2. Information we collect

Information you give us:

  • Account information: your email address, display name, a hash of your password (never the password itself), two-factor authentication settings, and preferences such as units, language and notifications.
  • Household information: household names, members, their roles and invitations. If you invite someone, we collect their email address from you.
  • Vehicle information: make, model, year, VIN, license plate, odometer readings, purchase details and any value you enter for the vehicle.
  • Records: service, repair and upgrade history, fuel and charging records, costs, vendors, parts, tires and tire readings, inspections, reminders, warranties, insurance and registration details, trips and mileage, notes and custom fields.
  • Files: photos, receipts and documents you upload, which can include insurance and registration papers that show names, addresses and policy numbers.
  • Inbound email: messages and attachments sent to your household's email-in address, including the sender's address.
  • Messages you send us, for example support requests.

Information collected automatically:

  • Security and audit logs: sign-ins, sensitive actions and authorization decisions, with the IP address, browser user agent and time.
  • Session data: a session identifier stored in a cookie and on our servers while you are signed in.
  • Push notification subscriptions, if you turn web push on.
  • Usage analytics and error reports, as described under Cookies and analytics.

Information from third parties:

  • From Stripe: your customer and subscription identifiers, subscription status, and limited payment details such as card brand and last four digits. We never receive your full card number.
  • From the US National Highway Traffic Safety Administration: vehicle details decoded from a VIN, and recall notices for your vehicle's make, model and year.

3. How we use information

  • To provide the Service: storing and displaying your records, calculating costs and efficiency, producing reports and exports, and sharing records with the people you choose.
  • To send the notifications you have asked for, such as reminders, recall alerts and expiry warnings, and service messages about your account, security and billing.
  • To read uploaded documents automatically, so that dates, amounts, vendors and similar details can be suggested for you to review.
  • To take payment and manage subscriptions.
  • To keep the Service secure: authenticating you, preventing abuse and fraud, rate limiting and investigating incidents.
  • To fix bugs and improve the Service, using aggregated analytics and error reports.
  • To meet legal obligations, such as keeping billing records, and to enforce our terms.

We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not use it to train AI models.

4. Automated document scanning

When a document is scanned, its text is read by software and AI models that run on our own infrastructure. If that cannot read a document, the document may instead be sent to Anthropic, PBC, the provider of the Claude AI models, which processes it on our behalf to extract the same details. Under its commercial terms, Anthropic does not use that content to train its models.

Scanned values are suggestions. Nothing is decided about you automatically, and you review the values before they become part of a record.

5. Who we share information with

We share information with service providers who process it for us, under agreements that limit them to that purpose:

  • Stripe, for payments and subscription management.
  • Our email delivery provider, for sending email to you and receiving mail sent to your email-in address.
  • Our hosting, storage and backup providers in the United States.
  • Anthropic, for document scanning as described above.
  • Sentry, for error reports. These are configured not to include personal information, and we do not record sessions.
  • Browser push services run by Apple, Google and Mozilla, which deliver web push notifications if you turn them on.

Some lookups send limited data to outside sources. Decoding a VIN sends the VIN to the US National Highway Traffic Safety Administration, and a recall check sends the make, model and year. Neither includes your name or account. Currency conversion fetches public exchange rates and sends no personal information.

We also share information:

  • With other members of your household, according to their roles.
  • With anyone who holds a share link, calendar feed URL or email-in address that you created. You control these and can revoke them.
  • When the law requires it, or when it is necessary to protect the rights, safety or property of our users, the public or us.
  • With a successor, if LugNote is involved in a merger, acquisition, reorganization or sale, or is transferred to a legal entity formed to operate it. This policy will continue to apply to your information, and we will tell you about the transfer.

6. Cookies and analytics

We use only the cookies that are essential to the Service: a session cookie that keeps you signed in and a token that protects against cross-site request forgery. We do not use advertising or third-party tracking cookies. The app also stores some data in your browser, such as drafts and cached records, so that it works offline. Signing out clears it.

For analytics we use Umami, which we host ourselves and which uses no cookies. It records the shape of a page and never its address: a vehicle page is recorded as a generic vehicle route, and a share link as a generic share route, so that no identifier, share token or page title reaches it. Browsers that send a Do Not Track signal are not counted at all.

7. How we protect information

  • Every record belongs to a household, and the database itself enforces that separation with row-level security, in addition to the application code.
  • Passwords are hashed with Argon2id. Two-factor authentication is available and recommended.
  • Traffic is encrypted in transit with TLS.
  • Location data and other EXIF metadata are stripped from photos you upload.
  • Public share links are read-only and limited to the sections you choose, and they never expose costs, documents or personal information.
  • Sign-in and public routes are rate-limited, and accounts lock temporarily after repeated failed sign-ins.

No system is perfectly secure. If a breach affects your personal information, we will notify you as the law requires.

8. How long we keep information

  • We keep your account and household data for as long as your account is open. Downgrading or cancelling a subscription does not delete anything.
  • When a household is deleted it can be restored for 30 days. After that, its records and files, including any full exports of it, are permanently deleted.
  • When you delete a document, or remove a document from the last record it was on, it is permanently deleted from storage 30 days later. Until then it still counts toward your storage use.
  • A full household export can be downloaded for 7 days. After that, the export file is deleted from our storage.
  • Security logs of sign-ins, failed attempts and changes to how you sign in are kept for 400 days and then deleted. You can see the last 90 days of your own in your security settings. A household's audit log is kept for as long as the household exists and is deleted with it.
  • When you delete your account it can be restored for 30 days by signing in. After that, your email address, name, password, two-factor settings, preferences, sessions, notifications and memberships are permanently removed. Records you added to a household that other people still belong to stay with that household, attributed to a deleted user rather than to you.
  • Backups are kept on a rolling basis, so deleted information can remain in backups for up to 90 days before it is overwritten.
  • Security and audit logs are kept for as long as needed to investigate abuse and protect accounts.
  • Billing and transaction records are kept for as long as tax and accounting law requires, even after an account is closed.

9. Your choices and rights

  • Access and export: you can export your records as CSV files or as a full household export, including files, at any time.
  • Correction: you can edit your profile and records in the app.
  • Deletion: a household owner can delete the household from its settings, and you can delete your account from your security settings. If you cannot do something yourself, write to privacy@lugnote.com.
  • Notifications: you can choose which notifications you receive, by type and by channel, in your settings. We will still send essential messages about security and billing.
  • Analytics: turn on Do Not Track in your browser and you will not be counted.

Depending on where you live, for example in California, you may have legal rights to know what personal information we hold about you, to get a copy of it, to correct it and to have it deleted, and not to be treated differently for exercising those rights. We extend these rights to all users. We do not sell or share personal information as those terms are defined in California law. To make a request, write to privacy@lugnote.com from the email address on your account. We will verify the request and respond within 45 days.

If you are a member of a household someone else owns, the owner controls that household's records. Ask the owner first about records there, and contact us if that does not resolve it.

10. Changes to this policy

We may update this policy. If a change is material we will tell you by email or in the app before it takes effect, and the effective date at the top will change.

11. Contact

Questions or requests about privacy go to privacy@lugnote.com.

Privacy Policy · LugNote